Fork-PR Actions Vulnerability in Gitea Affecting Private Repository Access
CVE-2026-58416

7.1HIGH

Key Information:

Vendor

Gitea

Vendor
CVE Published:
13 August 2026

What is CVE-2026-58416?

A security vulnerability in Gitea allows the Fork-PR Actions task to access a private repository that it should not have permission to read. This issue arises due to a missing guard on the collaborative-owner branch, thus enabling unauthorized reading of sensitive data in private repositories. Users of Gitea who manage access to repositories must upgrade to the latest versions to mitigate this risk and protect their private repository data.

Affected Version(s)

Gitea Open Source Git Server 0 <= 1.26.4

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

CassianStarck
.